The indexed-btree npm package can trigger malware during normal application activity
Daily Cyber News: The indexed-btree npm package can trigger malware during normal application activity
Projects using the indexed-btree N P M package may have executed malware during ordinary application activity. The package copied the identity of the legitimate sorted-btree library and recorded almost two million weekly downloads. However, it didn’t use a preinstall or postinstall script.
Key context: Once triggered, the code profiled the host, contacted attacker-controlled infrastructure, and retrieved a second-stage payload using information stored in a blockchain contract.
Additional detail: Download totals don’t show how many systems actually ran the malicious path, so teams need to distinguish between packages that were installed and packages used in a running process.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, malware, indexed-btree, package, trigger, during, normal, application.